this post was submitted on 07 Jul 2023
65 points (97.1% liked)

Mbin Blog Updates

7 readers
1 users here now

Blog updates for Mbin (fork of /kbin). Upcoming features, issues or anything else related Mbin or the fediverse.

Just follow this magazine to keep yourself up-to-date!

founded 1 year ago
MODERATORS
 

Dear kbin server owners, upgrade your Kbin instance now! Ernest just merged a critical hot fix into the develop branch.

If you don't update, your Kbin instance is vulnerable for HTML/JS injection. Which allows bad actors to do very nasty things on your instance and attack your visitors on your site.

Commit: https://codeberg.org/Kbin/kbin-core/commit/8ee87ba9fbb3192865dfebb054bec3da56b9493e

top 9 comments
sorted by: hot top controversial new old
[–] [email protected] 30 points 1 year ago (2 children)

Thanks the hot tip, I'm attacking eveny kbin instance while I still can!

[–] [email protected] 15 points 1 year ago

Thanks you for your compassion.

[–] [email protected] 1 points 1 year ago (1 children)
[–] [email protected] 1 points 1 year ago (1 children)

That wasn't me, I was in the comfort of my living room jacking it to Sonic R34 all night last night

[–] Mic_Check_One_Two 3 points 1 year ago* (last edited 1 year ago) (2 children)

Honestly, the fact that kbin was open to injection attacks in the first place is hilarious. That’s like day 1 cybersecurity training.

Anyone have the Bobby Tables xkcd handy?

Edit: Found it.

[–] [email protected] 3 points 1 year ago* (last edited 1 year ago)

@Mic_Check_One_Two Actually it was just since recently the case. Kbin used to escape the content, of course.. But after an upgrade to a newer Markdown parser version, it was overlooked in a PR.

We are recently approved for the Codeberg CI, hopefully allowing us to setup a good CI/CD pipeline. Avoiding these kind of regressions in the first place. Kbin is still in beta.

[–] [email protected] 1 points 1 year ago

@Mic_Check_One_Two Oopsy.. now lemmy.world is hacked.

load more comments
view more: next β€Ί